diff --git a/templates/sast.yml b/templates/sast.yml index 028d190..7f1100f 100644 --- a/templates/sast.yml +++ b/templates/sast.yml @@ -55,6 +55,12 @@ gitlab-advanced-sast: variables: SAST_ANALYZER_IMAGE_TAG: 2 SEARCH_MAX_DEPTH: 20 + cache: + key: "scan-metrics-$CI_COMMIT_REF_SLUG" + fallback_keys: + - "scan-metrics-$CI_DEFAULT_BRANCH" + paths: + - "scan_metrics.csv" rules: - if: '"$[[ inputs.excluded_analyzers ]]" =~ /gitlab-advanced-sast/' when: never @@ -75,6 +81,7 @@ gitlab-advanced-sast: - '**/*.mjs' - '**/*.cs' - '**/*.rb' + - '**/*.php' brakeman-sast: extends: .deprecated-16.8 @@ -138,7 +145,7 @@ semgrep-sast: "$[[ inputs.excluded_analyzers ]]" !~ /gitlab-advanced-sast/ && "$[[ inputs.run_advanced_sast ]]" == "true"' variables: - SAST_EXCLUDED_PATHS: "$DEFAULT_SAST_EXCLUDED_PATHS, **/*.py, **/*.go, **/*.java, **/*.js, **/*.jsx, **/*.ts, **/*.tsx, **/*.cjs, **/*.mjs, **/*.cs, **/*.rb" + SAST_EXCLUDED_PATHS: "$DEFAULT_SAST_EXCLUDED_PATHS, **/*.py, **/*.go, **/*.java, **/*.js, **/*.jsx, **/*.ts, **/*.tsx, **/*.cjs, **/*.mjs, **/*.cs, **/*.rb, **/*.php" exists: - '**/*.c' - '**/*.cc' @@ -197,7 +204,7 @@ semgrep-sast: - '**/bootstrap*.yml' - '**/application*.yaml' - '**/bootstrap*.yaml' - + sobelow-sast: extends: .sast-analyzer image: